Sunday, 25 September 2016

tcpdump101.com - 0.99-0.6.1 Released

Another quick update here for http://tcpdump101.com


  • ASA "raw-data" (L3 network) captures working.
  • ASA "ethernet-type" (L2 data-link) captures working.
  • Compression added for online versions to increase speed. Downloaded versions remain uncompressed to work "out-of-the-box".
The remaining ASA capture types should be done soon however I don't have access to a 9.x series ASA at the moment so I may not be able to properly add and test the "asa_dataplane" capture type. Hopefully I will be able to in the future. As always, feel free to reach out to me on Twitter @Grave_Rose for feedback.

Happy Packet Hunting!

Gr@ve_Rose

Wednesday, 21 September 2016

tcpdmp101.com - 0.99-0.5.3 Released

Just some bug fixes for tcpdump101.com

  • Fixed the "fw monitor" section which now adds operands automatically when creating a new filter.
  • Unlinked all the operand radio buttons.
Happy Packet Hunting!

Gr@ve_Rose

Tuesday, 20 September 2016

tcpdump101.com - 0.99-0.5.2 Released

Bug fixes and new bugs found for http://tcpdump101.com

Bug Fixes

  • Fixed an issue with the "fw monitor" section not being able to set Layer-4 ports
New Bugs
  • The "fw monitor" section does not automatically add operands when creating more than one filter. Users need to change the operands manually even if they want the "and" default.
  • In general, all operands are linked together across all PCap sections. Although I strongly doubt users will be using all PCap types at the same time, it is known and will be fixed.
Happy Packet Hunting!

Gr@ve_Rose

tcpdump101.com - 0.99-0.5.0 Released

New Features for http://tcpdump101.com


  • Changed a lot of the sliders to radio buttons which now display the options and full information at a quick glance instead of having to figure out what slider options do.
  • Modified the "Highlight" button to a "Copy" button. This will either copy the full command into your copy buffer (if your browser supports it) or it will just highlight the command for you to copy manually with ^C. Either way, a message will notify you whether or not the copy was successful.
  • Changed where the help icon (?) was on the Filter Options - Before it was at the title which, due to the CSS, caused the icon to move when hovered over. I moved it to the first filter option area instead.
As usual, feedback is welcomed. Reach out to me on Twitter @Grave_Rose or e-mail me directly at: tcpdump101 [at] gmail -dot- com

Happy Packet Hunting!

Gr@ve_Rose

Wednesday, 7 September 2016

tcpdump101.com - 0.99-0.4.0 Released

Hey everyone,

I've just launched the new framework version of http://tcpdump101.com Here are lists of new features as well as things to come:

New Features
  • Two themes: Light and Dark (default)
  • Everything in one single page - No need to jump between different URLs
  • All JS in one single file
  • Complete UI redesign
  • Keyboard shortcuts (found in the "Settings" bar)
  • CSS overlays instead of new "popped" tabs for top bar links
  • Minor fixes such as ICMP working  for "fw monitor"
  • A "highlight" button which will highlight the command so you can copy it right away
Things to Come
  • Finishing the ASA capture options - There are quite a lot of them
  • Modifying the "highlight" button to instead be an automatic "copy to copy buffer" button while still maintaining the "highlight" option for older browsers
  • Stylizing more of the HTML objects with CSS to match themes instead of just being browser defaults
  • Improving filter checking to avoid errors and bad PCap syntaxes
  • Adding a "snoop" (Solaris) section... Maybe?
I'm always looking for feedback so feel free to contact me either @Grave_Rose on Twitter or at tcpdump101 [at] gmail -dot- com

Happy Packet Hunting!

Gr@ve_Rose

Monday, 20 June 2016

tcpdump101.com - Version 0.4.0 Launched

http://tcpdump101.com - Version 0.4.0

New Features:
  • Added (basic) ASA PCap functionality.
  • Currently just does source/dest and sport/dport matching.
ToDo:

ASA Specific

  • Finish the ASA PCap functionality including:
    • asa_dataplane
    • asp-drop
    • ethernet-type
    • lacp
    • tls-proxy
    • webvpn
  • Not going to add IKE or ISAKMP since these can be generated in the regular PCap filters.
  • Going to add the ability to capture based on ACL.
General
  • Would like to collapse the code into a single page and use CSS for "layers" of the different PCap types. That's going to take a long time though.
Gr@ve_Rose